Sethi Family Guestbook Multiple Cross-Site Scripting Vulnerabilities
BID:39684
Info
Sethi Family Guestbook Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 39684 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2010 12:00AM |
| Updated: | Apr 26 2010 12:00AM |
| Credit: | Valentin |
| Vulnerable: |
Ricky J. Sethi Sethi Family Guestbook 3.1.8 |
| Not Vulnerable: | |
Exploit / POC
Sethi Family Guestbook Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
http://www.example.com/index.php?start=XX&number=~~XSS~~&bg=XX&f=XX
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
http://www.example.com/index.php?start=XX&number=~~XSS~~&bg=XX&f=XX
References
Sethi Family Guestbook Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Sethi Family Guestbook - Source Page (Ricky J. Sethi)
- Vendor Homepage (Ricky J. Sethi)